{"id":"CVE-2026-65423","summary":"o6 Automation open62541 Integer Overflow or Wraparound","details":"An integer overflow in the UA_Variant arrayDimensions product \ncomputation in open62541 may allow a remote attacker to trigger an \nout-of-bounds write.","modified":"2026-08-01T03:47:21.815803336Z","published":"2026-07-30T21:59:06.093Z","database_specific":{"cna_assigner":"icscert","cwe_ids":["CWE-190"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/65xxx/CVE-2026-65423.json","unresolved_ranges":[{"extracted_events":[{"introduced":"master"},{"last_affected":"master"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-08.json"},{"type":"WEB","url":"https://github.com/open62541/open62541/pull/8235/commits/b666d35769ce63998442e4d0810a3fb10b50179f"},{"type":"WEB","url":"https://github.com/open62541/open62541/pull/8236/commits/06b99fef667c8ec5bdf0605b4f00c84fcc1d3a60"},{"type":"WEB","url":"https://github.com/open62541/open62541/pull/8237/commits/1b71d9c5d9c4d02d4729b8903a52e9f530bf804e"},{"type":"WEB","url":"https://github.com/open62541/open62541/pull/8238/commits/afab4107bfd161da9ce8bb30ed77f3968c9c97df"},{"type":"WEB","url":"https://www.o6-automation.com/contact"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/65xxx/CVE-2026-65423.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-65423"},{"type":"ADVISORY","url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-08"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/open62541/open62541","events":[{"introduced":"0"},{"last_affected":"41f4deef34a9d0f94fcb830e2c831a9eb6236ade"},{"introduced":"84347820c8550b5750f2cd581c14ab201611c579"},{"last_affected":"f63e2a819aff6e468242dc2e54ccbd5b75d63654"},{"introduced":"b90fbfac5ef484089447bf5e3fe6ad7baaaebada"},{"last_affected":"dfd44a234645ed29cc6d190048bc8ae80c5454cd"}],"database_specific":{"extracted_events":[{"introduced":"1.3.0"},{"last_affected":"1.3.17"},{"introduced":"1.4.0"},{"last_affected":"1.4.16"},{"introduced":"1.5.0"},{"last_affected":"1.5.4"}],"source":"AFFECTED_FIELD"}}],"versions":["v1.5.4","v1.5.3","v1.3.17","v1.5.2","v1.4.16","v1.5.1","v1.4.15","v1.5.0","v1.3.16","v1.4.14","v1.4.13","v1.4.12","v1.4.11.1","v1.4.11","v1.4.10","v1.4.9","v1.3.15","v1.4.8","v1.4.7","v1.4.6","v1.3.14","v1.4.5","v1.3.13","v1.4.4","v1.3.12","v1.4.3","v1.4.2","prev-v1.4.2","v1.3.11","v1.4.1","v1.3.10","v1.4.0","v1.3.9","v1.3.8","v1.3.7","v1.3.6","v1.3.3","v1.3.5","v1.3.4","v1.3.2","v1.3.1","v1.3","v1.3-rc2-ef2","v1.3-rc2-ef","v1.3-rc2","v1.3-rc1","v1.2-rc1","v1.1","v1.1-rc1","basic256sha256","v1.1-dev","v1.0-dev","v1.0-rc3","v0.2.0-RC1","v0.1.0-RC4","v0.1.0-RC1","v0.0.0-150309","v0.1-automation14"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-65423.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}